discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

A critical security flaw in Keycloak's password reset feature allows unauthenticated attackers to take over any user account by forcing a password reset. Red Hat has released patches to address the issue.

By Swati Khandelwal·Aug 24·thehackernews.com·2 min read

Intelligence analysis by Llama

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Image: thehackernews.com

A vulnerability in Keycloak's password reset feature allows unauthenticated attackers to take over any user account. Red Hat has released patches to address the issue.

Why it matters

This flaw has significant implications for Keycloak users, as it allows unauthenticated attackers to take over any user account. It is essential to update to the latest version of Keycloak to prevent exploitation.

Imagine you have a secret password to keep your account safe. But, there's a way for someone to guess your password and take control of your account without even knowing your password. This is what happened with Keycloak's password reset feature. It's like a backdoor that lets someone in without a key.

Analysis

Root Cause of the Flaw

The root cause of the flaw is improper state validation within the reset-credentials authentication flow in Keycloak. This flow is triggered when a user requests password recovery. An attacker can exploit this flaw by sending a specially crafted request to the reset-credentials endpoint, which transitions directly to the password update phase without requiring the action token that Keycloak normally sends via email.

Impact of the Flaw

The flaw allows an unauthenticated remote attacker to take over any user account, including administrative accounts, by resetting their password. This is a critical security issue, as it enables an attacker to gain unauthorized access to sensitive information and potentially disrupt business operations.

Patching the Flaw

Red Hat has released patches to address the issue, including updates for the standalone server packages and container images for two RHBK streams. Users of upstream Keycloak are advised to update to version 26.7.2, while customers running Red Hat build of Keycloak (RHBK) should apply the updates shipped for 26.4.15 and 26.6.6. In the meantime, Red Hat has published a temporary mitigation – turning off the "Forgot password" functionality across all realms.

Key points

  • A critical security flaw in Keycloak's password reset feature allows unauthenticated attackers to take over any user account.
  • Red Hat has released patches to address the issue, including updates for the standalone server packages and container images for two RHBK streams.
  • Users of upstream Keycloak are advised to update to version 26.7.2, while customers running Red Hat build of Keycloak (RHBK) should apply the updates shipped for 26.4.15 and 26.6.6.
  • A temporary mitigation has been published – turning off the "Forgot password" functionality across all realms.
The Upside

If this flaw is patched quickly, users can rest assured that their accounts are secure. Red Hat's prompt response to address the issue demonstrates their commitment to security and customer trust.

The Downside

If the flaw is not patched promptly, it could lead to a significant security breach, compromising sensitive information and disrupting business operations. This would be a major setback for Keycloak users and could damage the reputation of the platform.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsapplication-securityenterprise-securityopen-sourcepassword-securitysoftware-securityvulnerability

Author

Swati Khandelwal

Intelligence analysis by

Llama

Published

Aug 24, 2026

Source

thehackernews.com

Share

Topics

application-securityenterprise-securityopen-sourcepassword-securitysoftware-securityvulnerability

Related

More from this desk

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·bleepingcomputer.com

Microsoft Teams now lets admins block external bots from meetings

Microsoft is rolling out a Teams meeting protection policy that lets administrators automatically block identified external bots from joining meetings, without requiring organizer approval.

Aug 24·bleepingcomputer.com

Microsoft: August updates break printing, PDF export in WPF apps

Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in some applications. The issue affects only apps that use the Windows Presentation Foundation (WPF) UI framework.

Aug 24·thehackernews.com

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups.